Ransomware victim disclosure
← All victimsRafael Advanced Defense Systems / Iron Dome Program
listed as From Shield to Shame · Claimed by Handala · listed 8 months ago
Status timeline
- ListedDec 6, 2025
- Data leakeddate unknown
At a glance
About the victim
AI dossier — public-source company profileThe leak post claims to expose the principal architects and developers behind Israel's Iron Dome missile defense system, a project primarily associated with Rafael Advanced Defense Systems and Israel Aerospace Industries (IAI), with U.S. co-development support from Raytheon. The Iron Dome is a mobile air defense system designed to intercept short-range rockets and artillery shells. The threat actor frames this as revealing sensitive technical or personnel information related to the program.
- Industry
- Defense & Aerospace (Missile Defense Systems)
Attack summary
Severity: critical — The claimed target is a national missile defense program; any exfiltration of personnel identities, technical data, or organizational intelligence from a defense system of this nature constitutes a critical-severity disclosure involving sensitive government/defense data with potential national security implications.The Handala group claims to have exfiltrated data exposing individuals and organizations behind Israel's Iron Dome defense system, framing it as a deanonymization or intelligence exposure operation; the post implies sensitive defense-related data has been published.
Data the group says was taken
AI dossier — extracted from the leak post- Personnel identities (architects/engineers of Iron Dome program)
- Organizational affiliations
- Potentially classified defense program documentation
What the group claims
The veil has finally been lifted. The main architects behind Israel’s so-called “Iron Dome” have now been exposed to the world. For years, the Zionist regime boasted about this so-called invincible shield, using it as a symbol of their so-called technological edge. But reality always finds its way in. Let it be known: the Iron…
Sources
Source
Indexed 8 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

